SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3661

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution.

HIGH 8.4EPSS 0.32%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

CVSS 3.1
8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.32% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
hp/z1 all-in-one g3 firmware · hp/z2 mini g3 firmware · hp/z2 mini g4 firmware · hp/z2 mini g5 firmware · hp/z2 small form factor g4 firmware · hp/z2 small form factor g5 firmware · hp/z2 small form factor g8 firmware · hp/z2 tower g4 firmware · hp/z2 tower g5 firmware · hp/z2 tower g8 firmware · hp/z238 microtower firmware · hp/z240 small form factor firmware · hp/z240 tower firmware · hp/z4 g4 firmware · hp/z440 firmware · hp/z6 g4 firmware · hp/z640 firmware · hp/z8 g4 firmware · hp/z840 firmware · hp/zcentral 4r firmware
Source
hp-security-alert@hp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.